Trojan

Should I remove “Trojan.Win32.Injuke.epvk”?

Malware Removal

The Trojan.Win32.Injuke.epvk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Injuke.epvk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

cirnoix.diandian.com
ocsp.digicert.com

How to determine Trojan.Win32.Injuke.epvk?


File Info:

crc32: F19672F2
md5: e06ad59240f89ceafd176891a3c545ec
name: E06AD59240F89CEAFD176891A3C545EC.mlw
sha1: 551cbd804e1dafce1b699a700fd0cf918f2965c8
sha256: eeaa1eb9028ffdd31cee74f77ab79cd45343a5505274d7795bb1d6ee314f74d0
sha512: 58a1b46586e4ca2695e4c0203b399e70e009a4652cfa762bbb2c20e5c6fec5e784e3a9152d84128bc5b240ea516c79c9f133f0fa7eec1dd96ebe53060650705a
ssdeep: 12288:0i6aVgmhvr80NqZjuJLpBeyfLXedKRy1t0BBqLJo/iKZBk4:0Mgmhj80w+Lqyzez1t0WVo6KZS4
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: CirnoIX x7248x6743x6240x6709 199X - 20XX
FileVersion: 1.3.0.0
CompanyName: CirnoIX
Comments: x5de5x5177x4ec5x4f9bx5b66x4e60x4ea4x6d41 x8bf7x52ffx7528x4e8ex6e38x620fx548cx5546x4e1ax7528x9014
ProductName: x2468 Box
ProductVersion: 1.3.0.0
FileDescription: x5de5x5177x4ec5x4f9bx5b66x4e60x4ea4x6d41 x8bf7x52ffx7528x4e8ex6e38x620fx548cx5546x4e1ax7528x9014
Translation: 0x0804 0x04b0

Trojan.Win32.Injuke.epvk also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 005071f51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
AlibabaTrojan:Win32/Injuke.573b8f86
K7GWAdware ( 005071f51 )
Cybereasonmalicious.04e1da
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Ramnit-9867597-0
KasperskyTrojan.Win32.Injuke.epvk
NANO-AntivirusTrojan.Win32.Obfuscate.dvquwe
TencentMalware.Win32.Gencirc.10c86844
SophosGeneric PUA FF (PUA)
BitDefenderThetaGen:NN.ZexaF.34236.Ii0faSFY!Ifb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.e06ad59240f89cea
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Bagsu!rfn
McAfeeGenericRXAA-FA!E06AD59240F8
VBA32BScope.Trojan.Occamy
TrendMicro-HouseCallTROJ_GEN.R002H07F121
YandexTrojan.GenAsa!6m7X4wuQV6g
IkarusTrojan.Win32.Yakes
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Injuke.epvk?

Trojan.Win32.Injuke.epvk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment